Continuous Adversary Operations Service (CAOS)

Continuous red teaming

A persistent, objective-driven adversary simulation program. Senior operators run attacks against your environment year-round, in cycles, with findings logged in real time.

Objective
Critical business services
Maturity
SOC responding as normal
Method
Year-round cycles
Result
Improvement across cycles

Adversary operations that do not stop

CAOS is a persistent, objective-driven adversary simulation program delivered by a dedicated team of senior operators. They run attacks against your environment throughout the year, using the tactics, techniques and procedures real adversaries employ against your sector, testing technical controls, people and processes under sustained pressure.

Reports follow each cycle, documenting results, observations, recommendations and improvements since previous cycles. Key operational activity is logged in real time on HackTrack, and your security team is given access once an execution cycle completes.

Objectives and outcomes

Test under sustained pressure

Operations run continuously rather than within a fixed window, so controls, people and processes are exercised the way a persistent adversary would exercise them

Keep pace with change

New systems, new exposure and completed remediation are tested as they appear, instead of waiting for the next annual assessment

Exercise incident response

Where an objective is reached without detection, operators can deliberately trigger an alert so the security team runs its response process for real

Show improvement over time

Each cycle report records observations and improvements since the previous cycle, and earlier test cases can be replayed to check whether detection has improved

Is CAOS the right fit?

CAOS suits organisations that already run detection and response and want it tested continuously. A SOC operating normally during operations is a prerequisite, because deliberately suppressing detection invalidates the result for that period.

CAOS fits when

  • Run a SOC, internal or managed, that will detect and respond as it would to a real threat during operations.
  • Need evidence of security improvement over time rather than a single point-in-time result.
  • Have critical business services worth defining as objectives.
  • Can nominate a Control Group of senior staff able to make risk-based decisions throughout.

How a cycle runs

Four phases, repeating. Each iteration begins by agreeing what the next cycle should prove.

The cycle A cycle is not time-boxed. It closes when the objectives are met, and the next one begins by agreeing what it should prove.
  1. 01

    Preparation

    • A workshop defines the critical business services, the cycle objectives, the Control Group and the communication channels, including an emergency channel
    • Rules of engagement are agreed, covering any staff, techniques or systems that must not be targeted, along with the checkpoint cadence
    • The output is a Cycle Execution Plan, approved by both parties before execution begins, and the reference point for the cycle
  2. 02

    Cycle execution

    • Operators run a campaign of attacks against the cycle's objectives. A cycle is not time-boxed; it is divided into Pushes and Checkpoints
    • Each checkpoint reviews where attacks succeeded, where controls prevented or detected them, what incident response was observed, and the goal for the next push
    • The Control Group shapes the next push, and can grant a concession where an objective has blocked progress across several pushes
    1. Breach

      • Deep reconnaissance profiles the organisation, its staff, third parties and subsidiaries, and is repeated continually as access and knowledge grow
      • Effort runs in parallel across three pillars: identity, social engineering and internet-facing services
      • Attacks on identity and exposed attack surface continue after a successful breach, building redundant access for use after eviction or in later cycles
    2. Privilege escalation and persistence

      • Internal reconnaissance builds an understanding of on-premises systems, cloud platforms and SaaS applications, and runs continuously
      • Insecurely stored credentials, post-exploitation on compromised systems, and pivots into developer environments and code repositories provide routes to privileged access
      • Each action is weighed for its likelihood of detection against the value of the outcome
    3. Action on objectives

      • Systems associated with the objective are identified along with the users who can reach them, and a plan is formed to compromise both
      • Sufficient evidence is collected to show the objective was completed
  3. 03

    Close out

    • A Cycle Execution Report is delivered to the Control Group to distribute internally
    • A technical debrief walks through the report, and a separate executive debrief covers the objectives, approach, results and recommendations
    • The security team is given access to the engagement data in HackTrack, including operator logs and test cases aligned to MITRE ATT&CK
  4. 04

    Purple team (optional)

    • Before the next iteration begins, the TTPs used during the cycle can be replayed alongside the security team, together with techniques currently used by real threat actors
    • A cycle can also be dedicated to purple teaming, taking either a coverage-based or intelligence-led approach

Deliverables and cadence

Every cycle produces a plan, a report and two debriefs, with HackTrack tracking findings in between:

Adversary operations

Continuous

HackTrack platform access

Real-time findings tracking

Cycle execution plan

Per cycle

Checkpoint meetings

Roughly every two months

Checkpoint status document

Roughly every two months

Cycle execution report

Per cycle, up to two a year

Technical and executive debriefs

Per cycle, up to two a year

Purple team, optional

Per cycle, up to two a year

Why SilentGrid

A CAOS program is delivered by a named Lead and Specialist who stay with it for its duration, so the team builds and keeps a detailed understanding of your environment. Where a cycle needs depth in a particular domain, such as mobile, wireless, cloud-native attack paths, thick client or hardware and IoT, the relevant specialist joins the core team for that phase.

SilentGrid's consultants are hand-picked, and between them they have delivered red team engagements globally over decades, including CBEST for UK financial institutions and CORIE engagements in Australia. The long-running nature of CAOS lets the team adapt as trending and bleeding-edge techniques emerge, pivoting when an opportunity appears rather than waiting for the next engagement.

CREST ANZApproved company

Individual credentials across our team include

  • OSEE
  • OSCE3
  • OSED
  • OSEP
  • OSWE
  • GXPN
  • CRTO
  • CRTE
  • CRTP
  • OSCP
Meet the team

Common questions

How is CAOS different from an annual red team engagement?

A red team engagement measures your defences within a fixed window. CAOS runs year-round in cycles, so changes to the environment and the fixes made after each cycle are tested as they happen. Cycles are not time-boxed; they close when the objectives are met, sufficient effort has been spent, or a high-severity incident means the activity must be disclosed.

Who inside our organisation knows the program is running?

Only the Control Group: a small group of senior staff with the business knowledge and seniority to make risk-based decisions. Keeping the knowledge there is what makes the test of detection and incident response realistic.

What happens if our security team detects the activity?

Respond as though it were real. The Control Group can deconflict through the primary channel, or the emergency channel when urgent. If operators are evicted they use redundant access, and if removed entirely they attempt to breach again unless the Control Group grants an assumed breach concession.

What is HackTrack?

SilentGrid's platform for capturing operator logs, indicators of compromise and the techniques used during a cycle. Your instance holds the data from every cycle and purple team. Key techniques are visible to the Control Group during a cycle, and the full data set opens to your security team once the report is delivered, searchable and annotatable.

Can we direct what gets targeted?

Yes. Objectives are set in the preparation workshop, and at each checkpoint the Control Group shapes the next push. A cycle can also be run as an intelligence-led exercise against a specific threat, or as a dedicated purple team.

Ready to run it continuously?

Get started with CAOS

Tell us which business services matter most, and we will scope the first cycle around them.

Onboarding begins with a workshop that defines the objectives, the Control Group and the rules of engagement, and produces a cycle execution plan for approval before any operation starts.